398/69 Tuesday, July 21, 2026

Reports indicate that attackers have begun exploiting CVE-2026-6875 in the ServiceNow AI Platform, according to threat intelligence firm Defused. ServiceNow AI Platform, formerly known as the Now Platform, is an enterprise Platform-as-a-Service (PaaS) solution that helps organizations integrate AI into core business workflows. The vulnerability was discovered and reported by Searchlight Cyber on April 1, 2026. The company stated that it could allow unauthenticated attackers to escape the sandbox and achieve remote code execution (RCE) within the ServiceNow Platform, although exploitation is highly complex.
ServiceNow has already remediated the vulnerability in hosted instances and released security updates for self-hosted instances on July 13, 2026. However, Defused researchers stated that exploitation attempts began over the past weekend, with the first attempt observed on Friday, just a few days after ServiceNow released the patch. Researchers noted that the observed payload targeted the same pre-authentication endpoint previously disclosed by Searchlight Cyber, /assessment_thanks.do, but used a different sandbox-escape gadget chain from the published proof of concept to achieve the same code execution capability.
ServiceNow has not stated in its official advisory that the vulnerability has been actively exploited and continues to say that it has no information indicating exploitation against ServiceNow instances. However, the company recommends that customers who have not yet taken action urgently update to the fixed versions to reduce the risk of attack. Last month, ServiceNow also disclosed a security incident involving queries against customer instances through an unauthenticated access vulnerability in a problematic API endpoint. The company later clarified that the activity was more likely linked to security researchers or customer testing related to bug bounty activity rather than malicious threat actors.
